The suggestion usually arrives from outside the security team. A phishing page is impersonating your login screen, marketing has watched a DMCA form clear a stolen product photo in the past, and someone asks why the same route can't clear this one too. It's a fair question, and the answer sits in the statute rather than in anyone's opinion of the services that file the notices.
Notice-and-takedown under the Digital Millennium Copyright Act was written for one problem: someone publishing a work you own without permission. A phishing page may borrow your logo, but the harm comes from a domain that reads as yours and a form that collects passwords, and the copyright process has no vocabulary for either.
None of this is legal advice. What follows describes what section 512 actually requires, where its one written clock points, why the mechanism assumes a counterparty a phishing operator will never be, and which levers were written for phishing instead, so the conversation with counsel can start from the text.
What a DMCA takedown service is built to do
A DMCA takedown service prepares and files notices under section 512 of the US Copyright Act, on your behalf, with the providers hosting content that infringes a copyright you hold. Congress passed the DMCA in 1998, and the US Copyright Office describes section 512 as a system that lets copyright owners have infringing online content removed without the need for litigation. For the basics, start with what a DMCA takedown notice is. This article is about whether to file one at all.
The mechanism runs on an exchange. The statute shields a provider from monetary liability for infringement of copyright by reason of the storage at the direction of a user, provided it meets certain conditions, and one of those conditions is acting on valid notices. Providers are also protected from liability for good faith removal of material a notice identifies. That's why the process works when it works: the provider's own safe harbor depends on it.
The notice has to name a copied work
Everything in section 512 hangs on the word copyright. A trademark, in the USPTO's definition, is a word, phrase, or design that identifies your goods or services and indicates their source, while a copyright covers created works such as software code, photographs, and writing. A lookalike domain is a source-confusion problem, and a form that collects passwords is a fraud problem. The page may well copy some of your code or images along the way, but the copying isn't the part doing the harm.
The statute is specific about what a valid notice carries. Among other elements, it requires identification of the copyrighted work claimed to have been infringed and a statement that the complaining party has a good faith belief the use isn't authorized. If the page copies your logo pixel for pixel, there's something to identify. If it uses your brand name in the domain and a form that looks like yours, the notice has nothing to name, which is the question to put to counsel before anyone files: what work of ours is on this page, and is it the thing doing the harm?
Often the brand name is the whole trick. Interisle's Phishing Landscape 2025 study found that 8.9% of phishing domains contained a prominent brand name spelled exactly, 137,860 domains matching 762 well-known brands. That's the source-identification problem the trademark system exists for, and a copyright notice has nothing to say about it.
The only clock in the statute is "expeditiously"
Ask how fast a DMCA takedown service works and the honest answer is that the law doesn't say. Section 512 requires a provider, on receiving a valid notice, to respond expeditiously to remove, or disable access to, the material. No hour or day count is attached to that obligation anywhere in the section.
The Copyright Office examined this in its 2020 review of section 512 and reported that courts have read "expeditiously" using a flexible approach that takes into consideration the varying circumstances of each case. So the speed of a copyright notice is set by the provider's queue and its reading of the case, not by a statutory deadline, and any turnaround figure a service quotes is its own service level rather than the law.
The clock that is written down runs the other way
Section 512 does contain one timeframe, and it protects the person whose content was removed. If the subscriber files a counter-notice, the provider keeps its protection for the removal only by putting the material back not less than 10, nor more than 14, business days after receiving it, unless the complainant has first notified the provider that it filed a court action to restrain the subscriber. In plain terms, a counter-notice puts the page back within three weeks unless you've gone to federal court.
The Copyright Office's own assessment of that window is blunt. It found the period is both too long for legitimate speech to be blocked, and too short for a rightsholder to realistically prepare and file a federal lawsuit. For a pirated ebook, that's an inconvenience. For a credential harvesting page, it's a scheduled restoration.
A counter-notice also assumes an identifiable counterparty. It must include the subscriber's name, address, and telephone number, along with consent to the jurisdiction of a federal district court and agreement to accept service of process. A phishing operator working behind fabricated registration details can type those fields as easily as anyone else, and the statement under penalty of perjury that goes with them has little hold on someone who never intends to be found. The dispute the statute was designed to referee, two real parties with something to lose, doesn't exist here.
One more provision belongs in the same conversation with counsel. Section 512(f) creates liability for anyone who knowingly materially misrepresents that material is infringing, including damages and attorneys' fees. Whether a given notice crosses that line is a judgment for your legal team, and it's the reason a copyright theory shouldn't be stretched over a case just because the form is familiar.
Phishing is over before the paperwork starts
Set the statute's clock against the attack's. A 2020 USENIX Security study led by Arizona State University researchers, covering 4.8 million victim visits to phishing pages targeting one major financial brand over a year, found that detection came nearly 9 hours after the first victim visit on average, and that 62.73% of victims had already visited the page before it was detected. The average attack ran about 21 hours from first to last victim, and the earliest fraudulent transactions came less than an hour after a victim visit.
Individual targets move faster still. In Verizon's 2024 Data Breach Investigations Report, drawing on phishing simulation data from its partners, the median time to click a malicious link after opening the email was 21 seconds, with another 28 seconds to enter data. Those are people in awareness exercises, not confirmed victims, but there's little left to interrupt once a notice has been drafted, filed, and queued.
Volume closes the gap from the other side. The Anti-Phishing Working Group recorded 3.8 million phishing attacks across 2025, up slightly from 3.76 million in 2024, and 971,181 in the first quarter of 2026, a 13.8% rise from 853,244 in the quarter before. Each one stays live until someone reaches the party that controls it.
Phishing has levers written for it
Phishing is named in the contracts that govern domain names, and copyright isn't. Since April 5, 2024, amendments to ICANN's Registrar Accreditation Agreement and base Registry Agreement have required accredited registrars and registries for generic top-level domains to act on DNS abuse, which the amended agreements define, as ICANN's compliance advisory sets out, as malware, botnets, phishing, pharming, and spam used to deliver any of those. When a registrar holds actionable evidence that a domain is being used for phishing, it must promptly take mitigation action reasonably necessary to stop or disrupt that use, and it must confirm receipt of the report.
Two caveats belong here. ICANN's evidence standard is information sufficient for the registrar to make a reasonable determination on its own, so the report has to carry the case, and "promptly" has no number attached either: the advisory says the time needed to investigate varies, making it impossible to prescribe a fixed amount of time for an action to be considered prompt. The difference from section 512 isn't speed on paper. It's that the obligation was written for this exact abuse, and the evidence a reviewer needs is a rendered phishing page, not proof of authorship.
Which party holds the lever depends on how the domain came to exist. Interisle found that 77% of phishing domains were registered specifically to commit the crime, against 23% that were legitimate domains someone had compromised. A domain registered for the attack (a maliciously registered domain, in the study's terms) has no innocent owner, so the registrar can suspend it outright. A compromised domain belongs to a real business, and the fix sits with the hosting provider, which can remove the injected page while the legitimate site keeps running.
The intake points are older than the DMCA. RFC 2142 reserved the abuse@ mailbox in 1997, most providers run a web form alongside it, and ICANN Lookup returns the registrar of record and its abuse contact for any domain.
A third lever protects victims without removing anything. Reporting a URL to Google Safe Browsing puts a warning in front of users of Chrome and other browsers that use the service, which Google says helps protect over 5 billion devices every day. The page stays hosted and the domain still resolves, but during the hours a registrar or host is still reading your report, a browser warning is doing a job a copyright notice never could.
One notice per URL against a bulk-registered campaign
The last mismatch is in the unit of work. A copyright notice describes one work on one page at one provider, and a DMCA takedown service is organized around that unit. Phishing arrives in sets. Interisle counted nearly 37% of phishing domains as bulk-registered, across 70,541 sets at 174 registrars, and an operator who loses one domain from a set still has the rest, and the kit, ready to redeploy.
Verifying what's on the page adds a wrinkle. APWG's Q1 2026 report notes that phishers still use geo/IP blocking and user-agent blocking, and that a growing number of sites only show fraudulent content when the referrer is a certain site. A reviewer who opens the URL from a data center address with no referrer may see a harmless page, so the evidence has to show the fraud as the victim saw it: a rendered capture from the campaign's own path, the resolution chain, and the registration record.
This is where the campaign, not the page, becomes the unit. Bolster AI's automated takedown flow sends evidence-backed abuse reports to hosting providers, through API integrations where the provider supports them and by automated email where it doesn't, submits confirmed fraudulent URLs to global blocklists, and re-scans for recurrences. The lookalike domain monitoring feeding it watches DNS, zone files, WHOIS records, and certificate logs, which is how a maliciously registered domain can surface before the email wave. Put the same question to any vendor, Bolster AI included: when one URL in a campaign is reported, what happens to the rest of the set?
Where a copyright notice still fits
None of this retires the DMCA. When the harm is the copied work itself (a scraped article, a lifted product photograph, a pirated manual), the notice describes the problem accurately and the provider's safe harbor gives it a reason to act. That's the case the notice was built for.
A cloned login form that happens to include your logo puts the logo in the notice and leaves the credential form, the domain, and the email wave untouched. Credential harvesting against your customers is a phishing protection problem, and the request should reach the registrar, the host, and the browser, with counsel consulted before a copyright form gets filled in out of habit.
The questions to put to the case and to any vendor
Before anyone files anything, six questions sort the case, whoever ends up working it:
- Is there a copyrighted work of ours on this page, and is it the thing doing the harm?
- Was the domain registered for this attack, or is it a legitimate domain someone compromised?
- Which party holds the lever: the registrar, the hosting provider, or the browser blocklist?
- What happens to the case if the operator files a counter-notice, and who decides what comes next?
- What does the vendor do to reduce harm while the page is still up?
- When one URL in a campaign comes down, how does the vendor find and act on the rest of the set?
For the sequence once the case is scoped, the phishing site takedown process runs through routing, evidence, and confirmation in order, including a comparison of the DMCA and UDRP routes. Take the copyright questions to counsel: the statute is short, the Copyright Office has said what it thinks of the timing, and the decision on any particular page is theirs.
Bolster AI detects external threats including phishing sites, lookalike domains, fraudulent social accounts, fake mobile apps, fraudulent ads, and marketplace abuse, connects related infrastructure into a single campaign, and removes them. Detection and takedown run as one workflow rather than as two separate promises, with automation carrying the volume and Bolster AI analysts handling the cases that need judgment.
If you'd rather see a phishing case move through registrar, host, and blocklist in one workflow than argue it through a copyright form, book a demo and bring the last case a DMCA notice didn't close.
TL;DR: A DMCA takedown service files notices under section 512 of the US Copyright Act, which covers copyright infringement and requires a valid notice to identify a copied work. The statute's only speed requirement on the provider is "expeditiously," while its one written timeframe, the 10 to 14 business day window to restore content after a counter-notice, runs in the attacker's favor. Phishing detection already lags the first victim by nearly 9 hours on average, and the typical attack is over in about 21 hours. Phishing is named as DNS abuse in ICANN's registrar contracts, so the levers that fit are the registrar, the hosting provider's abuse desk, and browser blocklists, not a copyright notice.